As Intel faces stiffer competition on the performance front from rival AMD and up-and-coming Arm chipmakers like Apple and Ampere, the company is talking up its silicon security prowess. Over the past few years, the chipmaker has steadily expanded the security functionality baked into its processors.

Hardware-accelerated security capabilities are becoming increasingly important among enterprise IT teams, according to a recent Poneman Institute report commissioned by Intel earlier this year. The report “found that 76% of IT decision makers say it's highly important for their technology providers to offer hardware assisted capabilities to mitigate software,” explained Suzy Greenberg, VP of product assurance and security at Intel.

Intel has approached this challenge at a foundational level, said Amy Santoni, principal engineer at Intel. This includes things like “securely booting, understanding what firmware and software has been loaded, and provided capabilities to measure and attest to that information,” she said.

Beyond supply chain concerns associated with preventing tampering between manufacturing and deployment, Intel is also looking at ways to mitigate some of the most challenging attack vectors at the silicon level, said Tom Garrison, VP and GM of client security strategy at Intel.

“We uncover new classes of attacks, and then we build technology to keep those safe,” he said.

One example of this is control flow enforcement, which allowed Intel to mitigate a pervasive attack vector called return-oriented programming attacks. These attacks were “not detectable with any solutions that were in the market,” he explained. But, by implementing detection capabilities at the silicon level, Intel was able to prevent these attacks from executing.

Intel Works to Secure Data at Rest, at Play, in Transit

A key area of focus for Intel has been encryption. Intel's efforts in this arena have already won the chipmaker a lucrative government contract to develop new chips capable of advanced encryption technologies.

“Once we’re securely booted, we focus on workload protection and the protection of the data,” Santoni said.

This poses a challenge as data can be at multiple states: in use, in transit, or at rest, she explained. This typically involves encrypting that data while it’s not in use or while it’s in transit. However, increasingly chipmakers, like Intel, have grappled with encrypting data in use.

The challenge with this is it can be incredibly performance intensive. “It’s safe to say that some of these security technologies that we're talking about would seem to impact performance,” Greenberg said.

According to Mike Nordquist, director of business client planning at Intel, enterprises have long had to choose between performance — in other words, user experience — or security.

“It was always kind of a compromise,” he said. “The end users a lot of times will complain: ‘I’m getting a bad experience, something is moving slow, is there a scan running or something in the background.’ That's always been a friction point between end users and IT.”

To address this Intel has developed encryption accelerators to reduce the performance hit and help to eliminate this compromise. You can think of these accelerators almost like appliances in a kitchen. You could make toast in the oven, but it’s a lot slower and energy intensive than tossing a few slices of bread in a toaster. The same applies to security. If you want to do confidential computing, Intel’s processors will offload the hardest parts of that task to a section of the chip tailored to accelerating encryption workflows.

Intel’s Software Superchargers

To be clear, Intel isn’t trying to get into the software security game. They’re not trying to compete with the likes of McAfee, Palo Alto Networks, or Symantec. Instead, they’re essentially building security engines in the silicon substrate that speed up functions like encryption.

This has enabled the last few generations of Intel CPUs to process data without having to decrypt it first and without the hit to performance. It’s “a way for the app writer and the app developer to control, protect your data while it's in use,” Santoni said.

Combined with secure enclaves — what Intel calls Secure Guard Extension — customers also have a confidential location within the chip to execute sensitive data in isolation.

Beyond encryption, Intel is also positioning its integrated artificial intelligence (AI) functionality to do machine learning (ML). According to Nordquist, one use case might be to accelerate endpoint security agents running on client computers, allowing them more quickly detect things like ransomware before it can seize control of a system.

Microsoft’s Defender endpoint client is one such example, Nordquist said, adding that making these features available to software vendors is critical as Intel is only building the tool.

“We build in those capabilities but we're not delivering an end solution. We're relying on an ISV partner in that space,” he said.

Combatting Supply Chain Attacks

Another threat Intel is working to mitigate are supply chain attacks like the recent Solar Winds breach.

“There's really two types of supply chain attacks. One is a software-based attack like Solar Winds, and then there's physical supply chain attacks where you tamper with the device … either you exchange a component or you change the software that's running on some of those devices like firmware,” Garrison said.

Intel’s answer to these challenges was Compute Lifecycle Assurance, which was formed in December 2019.

“Compute Lifecycle Assurance is focusing on the four basic phases of any platforms life, the build phase, the transfer phase, the operate phase, and then the retire phase,” he said. “What security means in each of those phases is distinct and that's important to understand when you're thinking about supply chain.”

Security companies have invested heavily to ensure that the person sitting in front of the computer is who they claim to be, Nordquist said. However, this is only half the equation. “We also need to make sure that the device is the right device, that it hasn't been tampered in some way, and that's that sort of transparency that we at Intel are trying to drive in the industry,” he said.